Beskrivelse
WebDmitriev Protection is a compact and efficient security solution for WordPress sites:
- Brute-Force Protection: Limits failed login attempts on
wp-login.php. - Entry Point Security: Disables XML-RPC and prevents user enumeration via REST API and author query parameters.
- File Integrity Guard: Monitors critical files (
.htaccessandwp-config.php) for unauthorized changes. - Uploads Directory Guard: Automatically blocks PHP execution inside
/wp-content/uploads/. - Lightweight WAF: Filters dangerous URL parameters (SQLi/XSS), blocks malicious User-Agent signatures, and manages IP blacklists.
Installation
- Upload the
webdmitriev-protectionfolder to the/wp-content/plugins/directory. - Activate the plugin through the ‘Plugins’ menu in WordPress.
- Go to ‘WD Protection’ in the admin dashboard to configure settings and view threat logs.
FAQ
-
How does the plugin block brute-force attacks?
-
It tracks failed login attempts by IP address. If an IP exceeds 5 failed attempts within 15 minutes, access to the login form is temporarily blocked.
-
What happens if wp-config.php or .htaccess is edited?
-
The plugin calculates MD5 hashes of critical files. If a modification is detected, a notice appears in the admin panel allowing you to inspect and approve the new file state.
Anmeldelser
Der er ingen anmeldelser for denne widget.
Bidragsydere & udviklere
“WebDmitriev Protection” er open source-software. Følgende personer har bidraget til dette plugin.
BidragsydereOversæt “WebDmitriev Protection” til dit eget sprog.
Interesseret i udvikling?
Gennemse koden, tjek SVN repository, eller abonner på udviklerloggen via RSS.
Ændringslog
1.0.0
- Initial public release.
